WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Cyber Resilience – How to Block Microsoft OneNote Files from Delivering Malware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Cyber Resilience – How to Block Microsoft OneNote Files from Delivering Malware

Author: Alec Davison

Created: Tuesday, March 7, 2023 - 20:09

Categories: Cybersecurity, Security Preparedness

Since mid-December 2022, threat actors have been increasingly exploiting Microsoft OneNote files to deliver malware and compromise victims. Last week, WaterISAC shared a DHS report on attackers successfully utilizing weaponized Microsoft OneNote files for malware distribution. Threat actors, including ransomware gangs, are actively using this delivery method to infect organizations. Specifically, threat actors behind the QakBot campaigns successfully used this tactic to compromise an organization and infect its network with BlackBasta ransomware. To help organizations proactively defend against this activity, BleepingComputer posted comprehensive guidance on how to block malicious Microsoft OneNote files. Read more detailed guidance on blocking Microsoft OneNote at BleepingComputer.

Additional WaterISAC Reporting on the OneNote infection vector and/or Qakbot/Qbot:

  • Threat Awareness – Use of Microsoft OneNote to Spread Malicious Payloads Rising
  • Threat Awareness – Black Basta Ransomware Employs Qakbot in Latest Attack Chain
  • Qbot Displaces Emotet as Most Prevalent Malware in December 2022, New Report Finds
  • Threat Awareness – Threat Actors Exploiting Microsoft OneNote Attachments to Spread Malware
  • Threat Awareness – Qbot Steals Sensitive Data Minutes after the Initial Infection
  • Zscaler Report – OneNote: A Growing Threat for Malware Distribution

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar